The living system of record for security governance
Every claim starts as a declaration, is backed by evidence, and rises in confidence as it is verified. Your organization's security posture becomes a living, verifiable layer of knowledge — ready for every new assessment.
This is how a claim lives
One sentence. Who stated it, what backs it, when it was verified. All in the same record.
Identity & Access Management › Strong Authentication
All externally-exposed enterprise and third-party applications enforce MFA.
CLM-0047·Scope: All externally-exposed applications and their user accounts
Critical security updates are applied within 30 days.
Supplier declaration · 30 May 2026
On two internet-facing servers: a known vulnerability whose patch has been available for 96 days, and a legacy TLS version still enabled.
System observation · population: 24 external assets
Decision owner: Information Security Manager · rationale recorded
When declaration and observation disagree
The supplier declares what it has in place. The system records how it looks from the outside. When the two disagree, the gap becomes visible and calls for a decision.
317 claims, 14 domains. Mapped to widely accepted frameworks.
Status cannot be set by hand
At the core of Monmer is a ledger model that keeps the state of every claim current through events and evidence. A record holds for as long as the evidence behind it is current; when that evidence expires, the record is either renewed or its status changes on its own.
Add evidence or open an exception
There is no third option. No button marks a status compliant by hand. Because that button is what stops a record from being a record.
Exceptions do not extend quietly
Every exception and every risk acceptance carries a term. When it expires the decision returns to the table, and nobody has to remember it.
Every ratio says what it measures
64%, but 64% of what? Every measurement is shown together with its scope.
The whole period on one timeline
Every change takes its place on the timeline. So at the end of a period you see not only the current state, but how the portfolio changed over the course of it.
A new assessment was started.
A claim rose from declaration to system observation.
Contradiction detected, time-bound risk acceptance opened.
Exception expired, the decision returned to the table.
We come from the field
For years we ran security governance inside organizations. We built Monmer not from theory, but from the needs we met in the field.
Former CIO at a large enterprise group, leading technology & security strategy across companies of all sizes. Believes strong security should be structured, practical and scalable without unnecessary complexity.
What we do not promise
We treat an inflated promise as an unverified claim too. So we set out our limits.
- We do not produce a health score.
- A security score reduced to a single number hides the denominator behind it. We show the distribution of statuses; we do not grade.
- Not everything is verified automatically.
- For claims that rest on process documents such as policies, contracts and exercises, the highest level is reviewed evidence. This is not a shortfall; it is full verification for that kind of claim.
- We do not eliminate the audit.
- Periodic audit is a requirement of regulation, of contracts and of the board cycle. Continuous verification makes it practical and more honest; it does not replace it.
- We do not leave the decision to AI.
- A response is prepared and the record is written. But when a case requiring human review is detected, the flow stops and waits for approval.
Take your security governance to the next level
We are early, and we work deeply with a selected set of organizations. We start with your own requirement catalog.